Phishing Scammers Net $400K With Fake Uniswap Google Ads
The two flagged addresses held a combined 146 ETH worth around $306,000, at the time of writing, according to Etherscan. DeFiLlama said that “fake ads on Google are a common source of phishing attacks.” The crypto non-profit group Security Alliance (SEAL) reported in April that there was a “significant uptick” in phishing activity on Google search in March. SEAL said that attackers pay Google or hack legitimate advertiser accounts to run convincing fake ads impersonating popular crypto protocols to lure users. Threat actors outbid legitimate crypto exchanges and protocols to achieve a superior position within the “Sponsored results” section on Google Search. SEAL blocked over 356 malicious advertisement links, a number which is “representative of a steady volume of attacker-deployed Google Ads each week for more than a year,” it added. “The campaign is not slowing down, and we are receiving more reports from affected users.” The phishing ads used legitimate-looking URLs to bypass Google‘s automated checks, while a hidden secondary iframe loads the malicious payload, also invisible to Google’s detection. Victims land on convincing clones of real crypto apps, with all network traffic secretly routed through attacker-controlled servers, explained SEAL, reporting that $1.27 million in total funds were stolen between March 13 and 30. In









